CSRF Vulnerability in Roskus Prospero Flow CRM
CVE-2026-82911
5.1MEDIUM
What is CVE-2026-82911?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the OrderConfirmController of Roskus Prospero Flow CRM versions prior to 5.15.11. This vulnerability allows an unauthenticated attacker to confirm any pending order on behalf of a legitimate user by directing them to a specially crafted webpage. The issue arises because CSRF tokens are enforced only on HTTP methods that alter data (POST, PUT, PATCH, DELETE), leaving the GET request for order confirmation unprotected. As a result, attackers can leverage sequential order numbers to automate the confirmation of multiple orders in a single attack, bypassing user authorization completely.
Affected Version(s)
Prospero Flow CRM 0 < 5.15.11
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
DarĂo ChacĂłn
Mario Ălvarez
DarĂo Rivas Quero
Cristian FernĂĄndez Cornejo
Secur0 CNA
Gustavo Novaro
